Back to Database
Status published
High
CVE-2019-15715
MantisBT before 1.3.20 and 2.22.1 allows Post Authentication Command Injection,...
Vulnerability Description
MantisBT before 1.3.20 and 2.22.1 allows Post Authentication Command Injection, leading to Remote Code Execution.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-15715
Credits & Attribution
No credits recorded in the NVD database.
References
- https://mantisbt.org/bugs/changelog_page.php?project=mantisbt
- https://mantisbt.org/bugs/view.php?id=26091
- https://github.com/mantisbt/mantisbt/commit/fc7668c8e45db55fc3a4b991ea99d2b80861a14c
- https://github.com/mantisbt/mantisbt/commit/5fb979604d88c630343b3eaf2b435cd41918c501
- https://mantisbt.org/bugs/view.php?id=26162
- https://github.com/mantisbt/mantisbt/commit/7092573fac31eff41823f13540324db167c8bd52
- https://github.com/mantisbt/mantisbt/commit/cebfb9acb3686e8904d80bd4bc80720b54ba08e5
- http://packetstormsecurity.com/files/159219/Mantis-Bug-Tracker-2.3.0-Remote-Code-Execution.html
More from mantisbt
View All →CVE-2025-62520
MantisBT unauthorized disclosure of private project column configuration
Medium
5.3
CVE-2025-55155
MantisBT: Authentication bypass for some passwords due to PHP type juggling
Medium
5.4
CVE-2025-47776
MantisBT: Authentication bypass for some passwords due to PHP type juggling
High
8.8
CVE-2025-46556
MantisBT is Vulnerable to Denial-of-Service (DoS) attack via Excessive Note Length
Medium
6.5
CVE-2024-45792
MantisBT vulnerable to information disclosure with user profiles
Medium
5.3
Affected Vendor
mantisbt
View all reports →Affected Software
mantisbt
Vulnerable Versions:
1.0.0, 2.0.0
Timeline
Official Publish:
October 9th, 2019
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.